发表机构
Shandong University; Waseda University(山东大学; 早稻田大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
SparLeak利用稀疏注意力引发的GPU内存访问侧信道,通过相位感知攻击提取轨迹,实现查询属性推断与响应重建,在真实服务下成功率分别达90.9%和87.3%。
AI 中文摘要
稀疏注意力被广泛用于加速现代大语言模型(LLM)中的长上下文推理,但其依赖于输入的执行行为引入了此前未被探索的隐私风险。我们识别出一种新的GPU微架构侧信道,称为稀疏性诱导的内存访问(Sparsity-Induced Memory Access, SIMA),它源于稀疏注意力所引发的依赖于秘密的键值缓存访问模式。基于这一观察,我们提出了SparLeak,一种相位感知的侧信道攻击,它在LLM推理期间提取SIMA轨迹,并实现两种实用的隐私提取:从预填充阶段轨迹中推断查询属性,以及从解码阶段轨迹中重建自回归响应。通过从页面级观察中重建近似的令牌级稀疏度轮廓,并应用基于轮廓的学习,SparLeak准确恢复敏感信息,包括用户查询属性和私有LLM响应内容。在三种LLM架构、三种稀疏注意力机制和三个隐私敏感数据集上的广泛评估表明,在真实世界的LLM服务设置下,SparLeak在属性推断上实现了90.9%的平均攻击成功率,在响应重建上实现了87.3%的平均攻击成功率,凸显了在部署基于稀疏注意力的LLM系统时考虑SIMA泄露的重要性。我们在以下网址提供匿名的SIMA轨迹、训练好的攻击模型、评估脚本和文档作为工件:此https URL。
英文摘要
Sparse attention is widely used to accelerate long-context inference in modern large language models (LLMs), but its input-dependent execution behavior introduces previously unexplored privacy risks. We identify a new GPU micro-architectural side channel, termed Sparsity-Induced Memory Access (SIMA), which arises from secret-dependent key-value cache access patterns induced by sparse attention. Based on this observation, we present SparLeak, a phase-aware side-channel attack that extracts SIMA traces during LLM inference and enables two practical privacy extractions: query attribute inference from prefill-phase traces and autoregressive response reconstruction from decoding-phase traces. By reconstructing approximate token-level sparsity profiles from page-level observations and applying profiling-based learning, SparLeak accurately recovers sensitive information, including user-query attributes and private LLM response content. Extensive evaluation across three LLM architectures, three sparse attention mechanisms, and three privacy-sensitive datasets shows that SparLeak achieves average attack success rates of 90.9% for attribute inference and 87.3% for response reconstruction under real-world LLM serving settings, highlighting the significance to account for SIMA leakage when deploying sparse-attention-based LLM systems. We provide anonymized SIMA traces, trained attack models, evaluation scripts, and documentation as artifacts at https://anonymous.4open.science/r/Janus_artifacts/.